10 papers
Reproducibility is Not Enough: Artifact Verifiability in Decentralized-Build Package Ecosystems
Oreofe Solarin, Kelechi Kalu, James C. Davis +1
Reproducible and verifiable builds increase trust in distributed software artifacts by enabling independent parties to detect artifacts produced by compromised build or release pip…
Cheap Code, Costly Judgment: A Case Study on Governable Agentic Software Engineering
James C. Davis, Paschal C. Amusuo, Tanmay Singla +2
Generative AI is shifting software engineering from a practice organized around scarce implementation effort toward one organized around abundant, low-cost code production. This sh…
AutoSOUP: Safety-Oriented Unit Proof Generation for Component-level Memory-Safety Verification
Paschal C. Amusuo, Ricardo Calvo, Dharun Anandayuvaraj +5
Memory-safety errors remain a persistent source of zero-day vulnerabilities in low-level software. The problem is especially acute in embedded systems, where hardware protections a…
Towards a Benchmark for Dependency Decision-Making
Tanmay Singla, Berk Ãakar, Paschal C. Amusuo +1
AI coding agents increasingly modify real software repositories and make dependency decisions, including adding, removing, or updating third-party packages. These choices can mater…
FalseCrashReducer: Mitigating False Positive Crashes in OSS-Fuzz-Gen Using Agentic AI
Paschal C. Amusuo, Dongge Liu, Ricardo Andres Calvo Mendez +3
Fuzz testing has become a cornerstone technique for identifying software bugs and security vulnerabilities, with broad adoption in both industry and open-source communities. Direct…
A Guide to Stakeholder Analysis for Cybersecurity Researchers
James C Davis, Sophie Chen, Huiyun Peng +2
Stakeholder-based ethics analysis is now a formal requirement for submissions to top cybersecurity research venues. This requirement reflects a growing consensus that cybersecurity…